Patentable/Patents/US-12126618
US-12126618

System and method for identifying an application initiating a communication in a computing environment

PublishedOctober 22, 2024
Assigneenot available in USPTO data we have
Inventorsnot available in USPTO data we have
Technical Abstract

System and method to identify a security entity in a computing environment is disclosed. Communication between a user computer and at least one destination computer by a security appliance is monitored by a security appliance. Selective information from the communication is extracted. A primary fingerprint is generated using a subset of the selective information. The generated primary fingerprint is evaluated for a match in an application ID database. When there is a match, corresponding application ID is assigned to the communication, wherein the application ID is associated with an application that generated the communication.

Patent Claims
13 claims

Legal claims defining the scope of protection, as filed with the USPTO.

2

2. The method of claim 1, wherein the extracted selective information is part of a handshake protocol of a secure communication protocol.

3

3. The method of claim 1, wherein the communication includes an un-encrypted portion and an encrypted portion and the extracted selective information is part of the un-encrypted portion of the communication.

4

4. The method of claim 1, wherein the extracted selective information is part of a client hello communication.

5

5. The method of claim 4, wherein the client hello communication is based on a BoringSSL protocol.

6

6. The method of claim 5, wherein the extracted selective information is a grease value.

9

9. The method of claim 1, wherein the communication is a Transport Layer Security (TLS) client hello packet and wherein the first subset of fields excludes TLS conditional extensions.

11

11. The system of claim 10, wherein the extracted selective information is part of a handshake protocol of a secure communication protocol.

12

12. The system of claim 10, wherein the communication includes an un-encrypted portion and an encrypted portion and the extracted selective information is part of the un-encrypted portion of the communication.

13

13. The system of claim 10, wherein the extracted selective information is part of a client hello communication.

14

14. The system of claim 13, wherein the client hello communication is based on a BoringSSL protocol.

15

15. The system of claim 14, wherein the extracted selective information is a grease value.

19

19. The method of claim 18 wherein the network packet is intercepted by a network tap device and received by the device from the network tap device.

20

20. The method of claim 18 wherein the network packet is a Transport Layer Security (TLS) client hello packet.

Classification Codes (CPC)

Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.

Patent Metadata

Filing Date

December 4, 2019

Publication Date

October 22, 2024

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “System and method for identifying an application initiating a communication in a computing environment” (US-12126618). https://patentable.app/patents/US-12126618

© 2026 Patentable. All rights reserved.

Patentable is a research and drafting-assistant tool, not a law firm, and does not provide legal advice. Documents we generate are drafts for review by a licensed patent attorney.